Praeferre/Frameworks/SOC 2
Security, Resilience & Assurance · United States (globally referenced)

SOC 2 — System and Organization Controls

An attestation framework built on the AICPA's Trust Services Criteria, used overwhelmingly by SaaS and technology vendors to demonstrate security, availability, confidentiality, processing integrity and privacy controls to enterprise customers.

REGULATORAmerican Institute of CPAs (AICPA) REGIONUnited States (globally referenced) EFFECTIVEOngoing — Type II reports cover a defined observation period, typically 6–12 months

Who it applies to

  • SaaS and technology service providers responding to enterprise due diligence
  • Organisations wanting independent assurance over their control environment
  • Vendors for whom a SOC 2 report shortens customer security review cycles

Key requirements

  • Controls mapped to the relevant Trust Services Criteria
  • Independent CPA firm assessment (Type I: point in time, Type II: over a period)
  • Evidence that controls operated effectively throughout the observation window
  • Increasingly, penetration testing evidence to support CC4.1 monitoring criteria
  • A formal report issued for controlled distribution to customers and prospects

Maximum penaltyNot statutory — an unfavourable opinion or lack of a report can directly affect enterprise sales and procurement outcomes

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates SOC 2 compliance

Continuous monitoring, evidence and reporting for SOC 2 — alongside every other framework you need to satisfy.